Low-power-consumption wireless sensing data transmission method and terminal
By establishing a secure associated data storage between the low-power wireless sensor terminal and the wireless access point AP, and using problem-request and problem-response messages for data transmission, the problem of time-consuming wireless connection and secure access authentication when the terminal wakes up from a deep sleep state, achieving lower power consumption and safe data transmission.
Patent Information
- Application Number
- CN202411458145.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-18
- Publication Date
- 2025-06-24
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
After waking up from a deep sleep state, existing low-power wireless sensor terminals need to undergo a time-consuming wireless connection and secure access authentication process, resulting in unsatisfactory energy consumption and long data transmission time.
By establishing a secure associated data storage between the terminal and the wireless access point AP, and when the terminal wakes up from a deep sleep state, it uses the problem-request message to send sensing service data to the AP. The AP performs data reception confirmation through the problem-response message, avoiding repeated wireless connection and secure access authentication processes.
It significantly shortens the overall time for the low-power sensor terminal to send sensing service data to the network side every time, reduces power consumption, and extends the battery power supply time, while ensuring the security of data transmission.
Smart Images

Figure CN120201107A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information communication, and particularly to a low-power wireless sensing data transmission method and a terminal. Background Art
[0002] Currently, in critical infrastructures such as power, WAPI wireless networks are used to transmit the data collected by sensor terminals to a server. For sensor terminals that are inconvenient to provide regular power supply, low-power wireless modules are used to achieve data transmission.
[0003] In order to save energy consumption and extend the battery usage time, a way of maximizing energy consumption savings is usually adopted, which is generally called the deep sleep mode. In the deep sleep mode, the low-power module turns off wireless radio frequency components, peripheral interface components, etc., so that the system is in the lowest power consumption state. Usually, it is awakened based on time or an external pin wake-up method to trigger the low-power module to enter the working state. After entering the working state, the low-power module first needs to connect to the wireless network, then perform data transmission, disconnect the wireless connection after completion, and enter the deep sleep mode again. At the current level, the power consumption index of a typical low-power module in the deep sleep mode is about 10 μA of current at 3.3 V voltage.
[0004] Each time the low-power module using the deep sleep mode wakes up from the sleep mode, it needs to perform a wireless connection. The time spent on this wireless connection is significantly longer than that of data transmission, and there are still unsatisfactory situations in terms of energy consumption savings. Summary of the Invention
[0005] The purpose of the present invention is to solve the disadvantages existing in the prior art, and to propose a low-power wireless sensing data transmission method and a terminal.
[0006] In order to achieve the above purpose, the present invention adopts the following technical solutions:
[0007] A low-power wireless sensing data transmission method is applied to a terminal and a wireless access point AP. The method includes:
[0008] S1: After the low-power wireless terminal establishes a wireless connection with the AP and completes WAPI authentication, both the terminal and the AP store the security association data of the wireless association.
[0009] S2: When the terminal wakes up from the deep sleep state and enters the working state, it first restores the security association data, then performs a channel scan to obtain the channel of the associated AP, and then sends a proble-request message to the AP. The proble-request frame contains a user information element VIE1, and the VIE1 includes sensing service data and security verification data.
[0010] S3: After receiving the proble-request message, the AP parses the VIE1 and performs a security check. If the security check passes, it records the sensor data and then replies to the terminal with a proble-response message. The proble-response frame includes the user information element VIE2, and the VIE2 includes received confirmation data and security verification data.
[0011] S4: After receiving the proble-response message, if the VIE2 is included therein, the data transmission is completed, and the terminal re-enters the low-power deep sleep state.
[0012] As a further solution of the present invention, the security association data includes the peer MAC address, the packet number PN of the service data, the channel information, the WAPI base key ID, i.e., BKID, and the session key.
[0013] As a further solution of the present invention, the security verification data in the VIE1 is formed by the terminal based on the security association data, includes the PN and BKID, and further includes the integrity check value MIC of the PN, BKID, and sensing service data.
[0014] The sensing service data and MIC in the VIE1 are ciphertexts, which are formed by the terminal encrypting through the recorded session key.
[0015] The security verification data in the VIE2 is formed by the AP based on the security association data, includes the PN in the VIE1 received by the AP, and the BKID recorded by the AP, and further includes the integrity check value MIC of the PN, BKID, and sensing service data. The access confirmation data and MIC in the VIE2 are ciphertexts, which are formed by the AP encrypting through the recorded session key.
[0016] The AP performs a security check on the VIE1, including: first decrypting the ciphertext data in the VIE to obtain the plaintext sensing service data and MIC value, then calculating the integrity check value MIC of the PN, BKID, and plaintext sensing service data in the VIE1 and comparing the integrity check values, and checking the replayability of the PN.
[0017] The terminal performs a security check on the VIE2, including: first decrypting the ciphertext data in the VIE2 to obtain the plaintext sensing service data and MIC value, then calculating the integrity check value MIC of the PN, BKID, and plaintext received confirmation data in the VIE2 and comparing the integrity check values, and comparing the PN in the VIE2 with the PN to be confirmed by the terminal.
[0018] A terminal, comprising a microcontroller MCU, a WLAN wireless information transceiver unit, and a storage unit capable of retaining data during deep sleep; characterized in that:
[0019] After the terminal establishes a wireless connection with an AP and completes WAPI authentication, it stores the security association data in the storage unit;
[0020] When the terminal wakes up from low-power sleep and enters the working state, it restores the security association data from the storage unit;
[0021] When the terminal wakes up from the low-power state and enters the working state, it sends the sensing service data to the AP by including the VIE1 in the Proble-request message in this way;
[0022] After each time the terminal sends a service packet, it increments the PN by 1 and stores the PN in the storage medium;
[0023] If the terminal does not receive the VIE2 in the Proble-request message, it is treated as an ordinary Proble-request frame for processing, including further initiating a wireless association request to establish a wireless connection with the AP, performing WAPI authentication, etc. to establish a secure wireless connection with the AP, and sending the sensing service data on this secure wireless connection using data packets.
[0024] One A wireless access point AP, after establishing a wireless connection with a terminal and completing WAPI authentication, records the security association data and does not immediately delete the security association data after the terminal disconnects; after receiving a Proble-request message, it checks whether it includes the VIE1 and performs a security check on the VIE1, and extracts the sensor data for local storage if the security check passes; after receiving a Proble-request message, it checks whether it includes the VIE1 and performs a security check on the VIE1, and extracts the sensor data for local storage if the security check passes; after receiving the sensor data sent by the terminal, it actively sends the sensing service data to the sensing data collection server, or sends the data to the sensing data collection server in response to a request from the sensing data collection server.
[0025] As a further solution of the present invention, the AP can also delete the recorded security data at a certain period, forcing the terminal to re-establish a wireless connection and perform WAPI security authentication, thereby triggering the security association data at both ends.
[0026] The beneficial effects of the present invention are as follows:
[0027] In the present invention: Through the solution provided by the present invention, when a low-power sensor terminal powered by a battery wakes up from the deep sleep state and enters the working state, it sends sensing service data to the wireless network side through proble-request, and the AP confirms the data reception through the proble-response message, avoiding the time-consuming wireless connection and secure access authentication processes, and can significantly shorten the overall time for the low-power sensor terminal to send sensing service data to the network side each time, thereby reducing power consumption and extending the battery power supply time.
[0028] In the present invention: During the data transmission process, security protection and inspection are also performed based on the security association data, which can ensure the security of data transmission. BRIEF DESCRIPTION OF THE DRAWINGS
[0029] Figure 1 It is an overview diagram of the transmission of sensing service data for a low-power sensor wireless terminal;
[0030] Figure 2 It is a composition diagram of VIE1 and VIE2 and a relationship diagram of proble frames;
[0031] Figure 3 It is a composition diagram of the wireless part of the low-power terminal;
[0032] Figure 4 It is a processing flow chart for the terminal to send data;
[0033] Figure 5 It is a flow chart for the AP to process the request message;
[0034] Figure 6 It is a flow chart for the terminal access and authentication process. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0035] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments.
[0036] It should be noted that, without conflict, the embodiments in the present application and the features in the embodiments can be combined with each other. Next, the present invention will be described in detail with reference to the drawings and in conjunction with the embodiments.
[0037] Embodiment 1:
[0038] A low-power wireless sensing data transmission method includes:
[0039] First, the security association data in this solution includes the peer MAC address, channel information, the WAPI base key ID (i.e., BKID), and the session key. Among them, BKID is the ID of the base key formed during the WAPI authentication process. It is a 16-byte integer derived from the base key. The session key is also a 16-byte key data derived from the base key and is used to encrypt service data.
[0040] In addition, the security association data also includes a message number, which uniquely identifies a sensing service data. When the terminal sends a sensing data, it increments the PN by 1 to achieve anti-replay for data transmission. In this embodiment, a 16-byte long integer is used, and the initial value is the WAPI convention initial value 0x5C365C365C365C365C365C365C365C36.
[0041] VIE1 and VIE2 are the abbreviations of Vendor Information Elements for the terminal and the AP to send and confirm sensing service data based on proble-request and proble-response messages. Their encapsulation is as Figure 2 shown. It includes type 501, length value 502, OUI and OUI-Type 503. The data part includes PN 504, BKID 505, service data 506, and MIC 507. Among them, the service data 506 is the ciphertext data obtained by encrypting the plaintext service data with the session key. The MIC is the ciphertext data obtained by encrypting the integrity check value of PN 504, BKID 505, and the plaintext service data with the session key. A preferred implementation of the encryption algorithm and the integrity check calculation algorithm used is to adopt the relevant algorithms specified by the WAPI protocol. Generally, the total length of the data part of a VIE is 254 bytes. After removing 16 bytes for PN, 16 bytes for BKID, and 16 bytes for MIC, there are 206 bytes available for sensor service data, and this length can meet the needs of general sensor data.
[0042] The security checks for VIE1 and VIE2 include: 1. Replay check. For the AP, it is to check whether the PN value in VIE1 in the proble-request message received by the AP is larger than the PN value recorded by the AP. For the terminal, it is to check whether the PN value in VIE2 in the proble-response message received by the terminal is equal to the PN value in VIE1 in the proble-request message sent; 2. Data integrity check, that is, the receiving party decrypts the service data and MIC in VIE1 or VIE2 in the received message with the session key in the security association data, and then calculates the data integrity of PN, BKID, and the plaintext service data in the VIE, and then compares it with the plaintext MIC.
[0043] VIE1 is the encapsulation for the low-power wireless sensing terminal to send sensing data to the AP, where the OUI-Typte is defined as 0x01, and the service data is the sensing service data.
[0044] VIE2 is the confirmation of the received sensing data sent by the AP to the low-power wireless sensing terminal, where the OUI-Typte is defined as 0x02, and the service data is the received confirmation data.
[0045] Next, the related processing methods and steps include:
[0046] S1: After the low-power terminal initially establishes a wireless connection 101 with the AP, completes the WAPI authentication 102, and performs key negotiation 103, both the terminal and the AP store the security association data 1041 and 1042 of the wireless association; thereafter, the terminal disconnects the wireless connection 105 with the AP and enters the low-power deep sleep state 106.
[0047] In the low-power sensing service, the sleep time of the terminal is usually at the minute level, typically 5, 10, or 15 minutes. With the solution of the present invention, the low-power terminal can sleep for a long time 107 because it does not need to maintain a connection with the AP.
[0048] During the process 1041 of the terminal storing the security association data, the terminal will save the MAC address, channel information, BKID, session key, and PN of the currently associated AP.
[0049] In order to be able to encrypt the service data and form security verification data based on these security association data after the low-power wireless unit module is awakened, the low-power wireless unit stores the data in a storage medium that can still maintain the data during the sleep period. In this instance, it is FLASH.
[0050] Similarly, the AP side will also store the security association data. Generally, the AP stores these data in the memory. When the AP restarts for some reason, there will no longer be the security association data of the terminal; in this case, the terminal and the AP will re-establish a wireless connection 101, perform WAPI authentication 102, and key negotiation 103, and the terminal and the AP will re-store and record the security association data 1041 and 1042.
[0051] S2: When the terminal wakes up from the deep sleep state and enters the working state 201, it first restores the security association data, then performs a channel scan 202 to obtain the channel of the associated AP, and then sends a proble-request message 203 to the AP. The proble-request frame contains the user information element VIE1, and VIE1 includes the sensing service data and the security verification data.
[0052] Low-power wireless terminals usually wake up the wireless transmission unit internally based on time or externally through pins. The wireless transmission unit is usually a microcontroller unit (MCU). After being woken up, the MCU reads security association data from the FLASH. The security association data includes the MAC address of the AP, i.e., the BSS address, and channel information. Usually, the channel of the AP does not change within a certain period. Therefore, the terminal can first perform beacon listening on the channel recorded in the security association data. If the AP recorded in the security association data is found on this channel, the terminal directly sends a probe-request message to the AP on this channel. If the recorded AP is not found on the recorded channel, it indicates that the channel of the AP has changed. Then the terminal will perform beacon listening on multiple channels in sequence to expect to find the AP corresponding to the security association data. If the AP is found, the terminal sends a probe-request message to the AP on the newly found channel. During this process, if the AP is not found, the terminal will scan other APs, and the terminal will establish a wireless association 101 with the new AP, perform WAPI authentication 102, and key negotiation 103, and of course, re-record the security association data 1401.
[0053] If the current terminal still has a wireless connection with the AP, the terminal sends sensing service data to the AP through a general wireless data frame. At this time, the security guarantee is provided by the general WAPI wireless data frame, which has data encryption and integrity check capabilities.
[0054] After the terminal wakes up from deep sleep and scans the AP, it sends data to the AP based on the method of including VIE1 in the probe-request message provided by this solution. At this time, the terminal performs security processing on the sensing service data based on the information in the security association data, including calculating the integrity check value using the packet number PN504, BKID505, and the plaintext sensing service data, and then encrypting and calculating the plaintext sensing service data and the aforementioned integrity check value using the session key in the security association data to obtain the service data 506 and MIC507 in the VIE1 encapsulation. During this process, the integrity check calculation algorithm and data encryption algorithm can adopt the algorithms specified by the WAPI standard.
[0055] S3: After receiving the probe-request message, the AP parses VIE1 and performs a security check. If the security check passes, it records the sensor data and then replies to the terminal with a probe-response message. The probe-response frame includes the user information element VIE2, and VIE2 includes receive confirmation data and security verification data.
[0056] In this process, when the AP processes the proble-request, it checks whether it includes VIE1, that is, searches for the VIE type of OUI-0x01 in the frame body of the proble-request. If VIE1 exists, it first performs a replay check according to the PN504 therein, and compares whether the BKID in VIE1 is consistent with the BKID in the security association data recorded by the AP. If both the replay check and the BKID are okay, it decrypts the service data 506 and MIC507 in VIE1 with the session key in the locally recorded security association record to obtain the sensing service data and the plaintext MIC, and then calculates the integrity check code MIC’ for the received VIE1, and compares the plaintext MIC and MIC’. If they are equal, VIE1 can be accepted.
[0057] In the case of VIE1 to be accepted, the AP makes a confirmation to the terminal through VIE2, which is by including VIE2 in the proble-response, where the service data of VIE2 is the received confirmation data. It should be noted that the PN504 in VIE2 is the PN value in the received VIE1, and at this time the AP also updates the PN value in the security association data record.
[0058] In the case that the terminal does not sense that the AP has restarted, the terminal may use the stale security association data to perform security processing on the service data. At this time, the AP will not be able to pass the security check on VIE1. In this case, in order to enable the AP and the terminal to continue to re-establish the wireless association and perform the WAPI and key negotiation processes, the AP will still reply to the terminal with a proble-response, but it does not include VIE2. That is to say, in this case, the AP treats it as a general Proble-request request for processing, and the replied proble-response is a general proble-response message.
[0059] As a preferred solution, the AP can also periodically trigger the update of the security association data of both parties. In this case, even if there is a trusted VIE in the proble-request message, the AP still does not include VIE2 in the proble-response.
[0060] S4: After the terminal receives the proble-response message, if it includes VIE2, the data transmission is completed, and the terminal re-enters the low-power deep sleep state.
[0061] In this process, after receiving the proble-response message, the terminal checks whether it includes VIE2 and performs a security check on VIE2. This process first compares whether the PN504 in VIE2 is equal to the PN value in the current security association record. If they are not equal, it discards the message. If they are equal, it further decrypts the service data 506 and MIC507 in VIE2, and on this basis, checks the integrity of the data. If it passes, the AP has received the sensing service data; in this case, the terminal enters the deep sleep state.
[0062] If the terminal does not find VIE2 when processing the proble-response message, it is considered that the AP has restarted the entire machine or the SSID service set ID associated with the terminal, or the AP has triggered an update of the security association data. At this time, the terminal performs the wireless association 101, WAPI authentication 102, and key negotiation 103 processes with the AP, and updates the security association data 1401.
[0063] Embodiment 2:
[0064] A low-power terminal, as Figure 3 shown, includes a microcontroller unit MCU601, a WLAN radio frequency transceiver unit 602, and a storage unit 603 that can retain data during deep sleep;
[0065] 1: The terminal, after establishing a wireless connection with the AP and completing WAPI authentication and key negotiation, stores the security association data in the storage unit. In this embodiment, the storage unit 603 uses FLASH, which can retain the stored information without loss in the low-power sleep state.
[0066] 2: The terminal, when waking up from low-power sleep and entering the working state, restores the security association data from the storage unit 603;
[0067] 3: The terminal, when waking up from the low-power state and entering the working state, sends the sensing service data to the AP by including VIE1 in the Proble-request message in this way;
[0068] 4: The terminal, after each sending of a service packet, increments the PN by 1 and stores the new PN in the storage medium;
[0069] 5: The terminal, if it does not receive VIE2 in the proble-response message, processes it as an ordinary proble-request frame, including further initiating a wireless association request to establish a wireless connection with the AP and performing WAPI authentication on this basis to establish a secure wireless connection with the AP, and sending the sensing service data on this secure wireless connection using data packets.
[0070] 6: Terminal. If the credibility verification of VIE2 in the proble-response message fails, discard the proble-response message and resend it.
[0071] Considering these characteristics of the low-power wireless sensing terminal, the behaviors and processes in various states after startup are as Figure 4 shown. After system initialization 701, channel scanning 702 will be performed. After discovering the target AP, connect to the AP, perform WAPI authentication, and key negotiation 703, then store the security association data 704. At this time, the packet sequence number PN of the message is the initial value 0x5C365C365C365C365C365C365C365C36. At this time, the terminal maintains a wireless connection with the AP. If the terminal has data to transmit at this time, the terminal sends the data to the AP through a wireless data frame 706. In this case, the PN value is incremented by 1 and the new PN value is stored 706, and then the terminal enters the deep sleep state 707; if there is no data to send at this time, the terminal enters the deep sleep state 707. After the terminal enters the deep sleep state 707, the terminal disconnects from the AP.
[0072] When the terminal is in the deep sleep state 707 and the wireless unit needs to send data to the network, the wireless unit is awakened by an external pin or an internal clock and enters the working state 708. After entering the working state, the MCU of the terminal wireless unit restores the security association data from the FLASH 709. At this time, the security association data is available in the memory of the MCU of the wireless unit, so that the data to be sent can be encrypted and security check data can be generated. In the working state, the terminal wireless unit starts scanning the channel 710 to discover the AP 711 recorded in the security association data. If the AP is scanned, a proble-request message is sent to the AP. This proble-request message contains the VIE1 information element. VIE1 is as Figure 5As shown in the figure, where the OUI-Type is 0x01, the PN value is the PN value in the current security association data plus 1, and the BKID is the BKID in the security association data; based on this information, the terminal wireless unit MCU calculates the integrity check code for PN, BKID, and the service data to be transmitted; further, the terminal wireless unit encrypts the service data to be transmitted and the integrity check code using the session key in the security association data, thus forming the encapsulated data of VIE1. Generally, the terminal will receive the proble-response message 713 sent by the AP, and then the terminal wireless unit checks whether the proble-response message has the VIE2 714 information element. If there is VIE2, it further checks the credibility of VIE2 715. If it is credible, the data transmission is successful, and the terminal enters the deep sleep state 707. If there is no VIE2 in the proble-response message, at this time the terminal wireless unit will send an association message to the AP, perform WAPI authentication and key negotiation 703, and then send the service data through the data frame. If the AP restarts the wireless service or the AP restarts during the terminal's sleep period, or triggers the update of the security association data, there will be a situation where there is no VIE2 in the proble-response message. On the other hand, if VIE2 is not credible, the terminal determines that there is a situation of a fake proble-response, and the terminal discards the received proble-response message 716, and then resends the proble-request message to the AP; for reliability, a certain number of attempt times can be set in the terminal implementation. If the credibility check of VIE2 still fails after multiple attempts, the terminal can re-initialize the entire wireless transmission unit.
[0073] In this embodiment, the AP, considering the relevant features, has the following process when processing the proble-request as Figure 5 shown. When the proble-request message 801 is received, the AP checks whether there is VIE2 802 in the proble-request message. If there is, it further checks the security of VIE2 803; if the security check passes, the AP replies to the terminal with a proble-response message 804, which contains VIE2, where the packet number PN of VIE2 is the PN in VIE1 included in the proble-request message. If the proble-request message does not include VIE1, the AP replies to the terminal with a general proble-response message that does not contain VIE2 805. If the security check of VIE1 in the proble-request message fails, the AP discards the received proble-request message.
[0074] The present invention: Through the solution provided by the present invention, when a battery-powered low-power sensor terminal wakes up from the deep sleep state and enters the working state, it sends sensing service data to the wireless network side through proble-request, and the AP confirms the data reception through the proble-response message, avoiding the time-consuming wireless connection and secure access authentication process, and can significantly shorten the overall time for the low-power sensor terminal to send sensing service data to the network side each time, thereby reducing power consumption and extending the battery power supply time. Further, during the data transmission process, security protection and inspection are also performed based on the security association data, which can ensure the security of data transmission.
[0075] For ease of description, spatial relative terms such as "above", "over", "on the upper surface", "above" etc. can be used here to describe the spatial position relationship of one device or feature to other devices or features as shown in the figure. It should be understood that the spatial relative terms are intended to include different orientations in use or operation in addition to the orientation of the device described in the figure. For example, if the device in the figure is inverted, the device described as "above" or "over" other devices or structures will then be positioned "below" or "beneath" other devices or structures. Thus, the exemplary term "above" can include both the orientations of "above" and "below". The device can also be positioned in other different ways (rotated 90 degrees or in other orientations), and the corresponding explanations are made for the spatial relative descriptions used here.
[0076] It should be noted that the terms used here are only for describing specific embodiments and are not intended to limit the exemplary embodiments according to the present application. As used here, unless the context clearly indicates otherwise, the singular form is also intended to include the plural form. In addition, it should also be understood that when the terms "comprise" and / or "include" are used in this specification, they indicate the presence of features, steps, operations, devices, components and / or their combinations.
[0077] It should be noted that the terms "first", "second", etc. in the description, claims and above-mentioned drawings of this application are used to distinguish similar objects and do not necessarily have to be used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances so that the embodiments of the present application described here can be implemented, for example, in an order other than those illustrated or described here. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that comprises a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0078] The above are only the preferred embodiments of the present invention and are not used to limit the present invention. For those skilled in the art, the present invention can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A low-power wireless sensor data transmission method, applied to a terminal and an AP, characterized in that: The method comprises: S1: After the low-power wireless terminal establishes a wireless connection with the AP and completes WAPI authentication, both the terminal and the AP store the wireless associated security association data; S2: The terminal wakes up from the deep sleep state and enters the working state, first recovers the security association data, then performs channel scanning to obtain the channel of the associated AP, and then sends a problem-request message to the AP, wherein the problem-request frame includes a user information element VIE1, and the VIE1 includes sensing service data and security verification data; S3: After receiving the problem-request message, the AP parses the VIE1 and performs a security check. If the security check passes, the sensor data is recorded, and then a problem-response message is replied to the terminal. The problem-response frame includes a user information element VIE2, and the VIE2 includes reception confirmation data and security verification data. S4: After the terminal receives the problem-response message, if the VIE2 is included in the message, the data transmission is completed, and the terminal re-enters the low-power deep sleep state.
2. A low-power wireless sensor data transmission method according to claim 1, characterized in that: The security association data includes the peer MAC address, the message number PN of the service data, the channel information, the WAPI base key ID (BKID), and the session key.
3. A low-power wireless sensor data transmission method according to claim 1, characterized in that: The security verification data in the VIE1 is formed by the terminal based on the security association data, including the PN, BKID, and the integrity check value MIC of the PN, BKID, and sensor service data; The sensor data and MIC in the VIE1 are ciphertexts, which are encrypted by the terminal using the recorded session key; The security verification data in the VIE2 is formed by the AP based on the security association data, including the PN in the VIE1 received by the AP, the BKID recorded by the AP, and the integrity check value MIC of the PN, BKID, and sensor service data; the access confirmation data and MIC in the VIE2 are ciphertext, which are formed by the AP through encryption using the recorded session key; The AP performs a security check on the VIE1, including: first decrypting the ciphertext data in the VIE to obtain the plaintext sensor service data and the MIC value, then calculating the PN, BKID, and the integrity check value MIC of the plaintext sensor service data in the VIE1 and comparing the integrity check values, and checking the replayability of the PN; The terminal performs a security check on the VIE2, including: first decrypting the ciphertext data in the VIE2 to obtain the plaintext sensor business data and the MIC value, then calculating the PN, BKID, and the integrity check value MIC of the plaintext reception confirmation data in the VIE2 and comparing the integrity check values, and comparing the PN in the VIE2 with the PN to be confirmed by the terminal.
4. A terminal, characterized in that: It includes a microcontroller MCU, a WLAN wireless information transceiver unit, and a storage unit capable of maintaining data in deep sleep; it is characterized by: The terminal, after establishing a wireless connection with the AP and completing WAPI authentication, stores the security association data in the storage unit; The terminal, when waking up from low-power sleep and entering a working state, recovers the security-related data from the storage unit; When the terminal wakes up from the low power consumption state and enters the working state, it will include the VIE1 in the Problem-request message, and in this way send the sensing service data to the AP; The terminal, after sending a service message each time, adds 1 to the PN and stores the PN in the storage medium; If the terminal does not receive the VIE2 in the problem-request message, it will be treated as a normal problem-request frame for processing, including further initiating a wireless association request to the AP to establish a wireless connection, performing WAPI authentication, etc., thereby establishing a secure wireless connection with the AP, and sending the sensor service data using a data message on this secure wireless connection.
5. A wireless access point AP, characterized in that: The AP, after establishing a wireless connection with the terminal and completing WAPI authentication, records the security association data, and does not immediately delete the security association data after the terminal is disconnected; After receiving the problem-request message, it will check whether the VIE1 is included and perform a security check on the VIE1. If the security check passes, the sensor data will be extracted and stored locally; After receiving the problem-request message, it will check whether the VIE1 is included and perform a security check on the VIE1. If the security check passes, the sensor data will be extracted for local storage; after receiving the sensor data sent by the terminal, the sensor business data will be actively sent to the sensor data collection server, or the data will be sent to the sensor data collection server in response to the request of the sensor data collection server.
6. The AP according to claim 5, characterized in that: The AP may also delete the recorded security data at a certain period, forcing the terminal to re-establish a wireless connection and perform WAPI security authentication, thereby triggering the security association data at both ends.